Re: [PATCH v2 net 0/3] ipv4/ipv6: Fix UAF and memory leak in IGMP/MLD
From: patchwork-bot+netdevbpf@kernel.org
Date: 2026-07-08 12:50:30
Hello: This series was applied to netdev/net.git (main) by Paolo Abeni [off-list ref]: On Sun, 5 Jul 2026 18:17:53 +0000 you wrote:
This series addresses two potential UAF vulnerabilities and memory leaks in the IPv4 IGMP and IPv6 MLD subsystems. The first two patches fix a UAF where the packet receive path races with device teardown. If the device refcount has already hit 0 (but the memory is still held by RCU), incoming IGMP/MLD packets trying to schedule delayed work or timers would call refcount_inc() on the 0 refcount, triggering a warning and eventually leading to a UAF when the work runs after the device has been freed. This is fixed by introducing safe hold helpers using refcount_inc_not_zero(). In MLD, we also ensure we only enqueue the skb if we successfully acquired the device reference, to avoid leaking skbs when the device is being destroyed. [...]
Here is the summary with links:
- [v2,net,1/3] ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
https://git.kernel.org/netdev/net/c/7b19c0f81ed1
- [v2,net,2/3] ipv6: mcast: Fix potential UAF in MLD delayed work
https://git.kernel.org/netdev/net/c/9b26518b6896
- [v2,net,3/3] ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
https://git.kernel.org/netdev/net/c/3546deaa0c30
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html